This agreement governs how invokwik processes the personal data its customers enter into the service, as required by Article 28 of the GDPR. It applies to every account under the Terms of Service. How invokwik handles its own customers' account data is described in the Privacy Policy.
1. Parties and scope
This Data Processing Agreement ("DPA") is entered into between the person or entity that holds an invokwik account (the "Customer") and Mirko Zagami, trading as invokwik (the "Processor"), contactable at support@invokwik.com. The Processor's postal address and VAT number are available on request.
This DPA forms part of the Terms of Service (the "Terms") and applies to all personal data the Processor processes on the Customer's behalf in providing the invokwik service (the "Service"). Accepting the Terms accepts this DPA; no separate signature is required. Where this DPA and the Terms conflict on the processing of personal data, this DPA prevails.
Notices to the Customer under this DPA are sent by email to the account owner or, where the account has no owner, to the members authorised to manage its billing, failing which to every member of the account.
Terms not defined here have the meaning given in Regulation (EU) 2016/679 (the "GDPR").
2. Roles of the parties
For the personal data the Customer enters into, or sends through, the Service ("Customer Personal Data"), the Customer is the controller, or a processor acting on behalf of its own controller, and the Processor is a processor.
The Processor acts as an independent controller for the data needed to run the Customer's account and subscription, such as the account holder's sign-in details and billing records. That processing is described in the Privacy Policy and is not covered by this DPA.
Subscription payments are handled by Stripe, which processes the Customer's own payment details for the Customer's subscription. Stripe receives no Customer Personal Data and is therefore not a sub-processor under this DPA.
3. Subject matter and duration
The subject matter, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.
This DPA applies for as long as the Processor processes Customer Personal Data, and ends once that data has been deleted under clause 12.
4. Processing on documented instructions
The Processor processes Customer Personal Data only on the Customer's documented instructions, including with regard to transfers to a third country, unless required to do otherwise by Union or Member State law. In that case the Processor will inform the Customer of the legal requirement before processing, unless that law prohibits it on important grounds of public interest.
The Terms, this DPA, and the Customer's use and configuration of the Service, such as creating, sending or sharing a document, together form the Customer's documented instructions.
The Processor will inform the Customer without undue delay if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection law.
5. Confidentiality
The Processor ensures that every person it authorises to process Customer Personal Data has committed to confidentiality or is under an appropriate statutory obligation of confidentiality, and processes that data only as needed to provide the Service.
6. Security of processing
The Processor implements and maintains the technical and organisational measures described in Annex 2, which are designed to ensure a level of security appropriate to the risk, as required by Article 32 GDPR.
The Processor may change those measures as the Service develops, provided that the overall level of security is not reduced.
7. Sub-processors
The Customer gives the Processor general written authorisation to engage the sub-processors listed in Annex 3.
The Processor will give the Customer at least 30 days' notice of any intended addition or replacement of a sub-processor, by notice under clause 1 and by updating Annex 3 on this page. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may end its subscription and request deletion under clause 12 before the change takes effect.
The Processor imposes on each sub-processor, by written contract, data protection obligations that provide sufficient guarantees in the manner required by Article 28(4) GDPR, and remains liable to the Customer for each sub-processor's performance of those obligations.
8. International transfers
The Service's database and file storage are hosted in the European Union, in Supabase's Frankfurt (Germany) region. Supabase, Inc. is a United States company; access by Supabase from outside the European Economic Area, for example to provide support, relies on the standard contractual clauses in Supabase's data processing agreement.
Resend, which delivers the emails the Customer sends, and Vercel, which hosts the web application and the pages behind share links, process data in the United States. Each is certified under the EU–U.S. Data Privacy Framework, and transfers to them rely on that framework under Commission Implementing Decision (EU) 2023/1795. Should a certification lapse, the Processor will rely on the standard contractual clauses adopted by Commission Implementing Decision (EU) 2021/914 or another transfer mechanism permitted by Chapter V GDPR.
The Service's web fonts are currently served by Google Fonts, which receives the IP address of anyone who loads a page of the Service, including a share page, and no other Customer Personal Data. Google is not engaged as a sub-processor and receives that data under its own terms. Google LLC is certified under the EU–U.S. Data Privacy Framework.
Onward transfers by a sub-processor, including support access from outside the European Economic Area, are governed by that sub-processor's own data processing agreement.
9. Data subject rights
Taking into account the nature of the processing, the Processor assists the Customer by appropriate technical and organisational measures in responding to requests from data subjects exercising their rights under Chapter III GDPR.
The Customer can access Customer Personal Data directly in the Service, and correct it there by editing a record or, where an issued document is locked, by voiding or replacing it. Deleting a document, client or sender in the Service archives it rather than erasing it; where a data subject's erasure request requires a record to be erased, the Processor will erase it on the Customer's written request within 30 days.
If the Processor receives a request directly from a data subject concerning Customer Personal Data, it will forward the request to the Customer without undue delay and will not respond to it except on the Customer's instructions.
10. Assistance with security and impact assessments
Taking into account the nature of the processing and the information available to it, the Processor provides the Customer with reasonable assistance in meeting its obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation with a supervisory authority.
11. Personal data breach
The Processor will notify the Customer of a personal data breach affecting Customer Personal Data without undue delay, and in any event within 48 hours of becoming aware of it, by notice under clause 1.
The notification will include, to the extent then known, the information listed in Article 33(3) GDPR. Where that information is not yet available, it will be provided in phases as it becomes available. The Processor will take reasonable steps to contain the breach and mitigate its effects.
Notifying a breach is not an acknowledgement of fault or liability.
12. Deletion and return
On termination of the Terms, the Processor keeps Customer Personal Data for 30 days, during which the Customer may ask for it to be returned, and then deletes it. At any time, on the Customer's written request to support@invokwik.com, the Processor will instead delete Customer Personal Data, or return it in a commonly used, machine-readable format, within 30 days. Both are subject to any storage that Union or Member State law requires.
Copies held in the hosting provider's backups are removed as those backups expire under the provider's retention cycle, and are not restored in the meantime except to recover from a failure of the Service.
While its subscription is active, the Customer can also download its documents as PDF files from the Service, and retrieve its data through the API where it holds an API key.
Ending a subscription does not delete Customer Personal Data, and does not by itself stop processing the Customer has set up: active schedules keep generating invoices, share links stay open until they expire or are turned off, and API keys keep working until they are revoked. Before ending a subscription, the Customer should pause its schedules, turn off its share links and revoke its API keys, or request deletion.
13. Audits and information
The Processor makes available to the Customer the information necessary to demonstrate compliance with Article 28 GDPR, including this DPA, the description of measures in Annex 2, and the data processing agreements and published security information of the sub-processors in Annex 3.
The Processor allows for and contributes to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer and bound by confidentiality. The Customer will give at least 30 days' written notice, will bear its own costs, and will not audit more than once in any twelve-month period, unless a personal data breach or a supervisory authority requires it. The Processor may first answer the Customer's questions in writing, and an on-site audit will take place only where those answers are reasonably insufficient.
14. Special categories of personal data
The Service is not designed for special categories of personal data under Article 9 GDPR, or for data relating to criminal convictions and offences under Article 10 GDPR. The Customer should keep such data out of free-text fields such as line descriptions, notes and references.
Where the nature of a document unavoidably reveals such data, for example a receipt for a health service, the Customer is responsible for having a lawful basis for that processing and for assessing that the measures in Annex 2 are appropriate to it.
15. Liability
The Processor's liability under this DPA is subject to the limitations of liability in the Terms, except where applicable law does not permit such a limitation. Nothing in this DPA limits the rights of data subjects under Article 82 GDPR.
16. Governing law and jurisdiction
This DPA is governed by the laws of Malta. The courts of Malta have exclusive jurisdiction over any dispute arising from it.
The Processor's lead supervisory authority is the Information and Data Protection Commissioner (IDPC) of Malta. This does not affect a data subject's right to lodge a complaint with the supervisory authority of their own Member State.
17. Changes to this DPA
The Processor may update this DPA. Material changes will be notified to the Customer by email at least 30 days before they take effect, except where a change is required sooner by law or by a supervisory authority. The effective date at the top of this page identifies the current version.
18. Contact
Questions about this DPA, requests under it, and notices to the Processor should be sent to support@invokwik.com.
Annex 1. Description of the processing
- Categories of data subjects
- The Customer's clients and their contact persons; persons the Customer pays or reports to on statements; the Customer's team members, as far as their details appear in the Customer's account; and any other person the Customer names in a document.
- Types of personal data
- Identification and contact details (name, company name, contact person, title, email address, telephone number, postal address); tax identifiers such as VAT numbers; payment details the Customer enters, such as bank account coordinates; document contents (line descriptions, amounts, dates, references, notes, and reasons recorded for voids and credit notes); email delivery data (recipient address and delivery status); and technical data incidental to providing the Service, such as IP addresses in request logs, including those of people who open a share link.
- Special categories
- None intended. See clause 14.
- Nature of the processing
- Storage, retrieval, organisation, rendering of documents to PDF, transmission by email at the Customer's direction, publication through share links the Customer creates, access through the API, and deletion.
- Purpose
- Providing the Service to the Customer under the Terms.
- Duration and frequency
- Continuous, for the term of the Terms and until deletion under clause 12.
Annex 2. Technical and organisational measures
- All connections to the Service, its API and its share pages are encrypted in transit with TLS.
- Customer Personal Data is stored by Supabase on Amazon Web Services infrastructure with encryption at rest (AES-256).
- Every record belongs to one organisation, and the database enforces that separation with row-level security, so members of one account cannot read another account's data.
- Database privileges are granted explicitly: every new table, view and function starts with no access, and receives only the access it needs.
- Passwords are held by the authentication service as salted hashes, never in plain text. Password reset links work once.
- API keys are stored only as a hash, are shown once when created, take effect on revocation from the next request, and are limited to 120 requests a minute per key.
- Only the account owner can invite members and create API keys. Billing is limited to the owner and the members the owner authorises.
- Share links use random, unguessable tokens. The Customer can set them to expire and turn them off, and a link that has been turned off or has expired never works again.
- Every change to the Service is reviewed and passes automated tests before it is deployed.
Annex 3. Sub-processors
| Sub-processor | Processing | Location |
|---|---|---|
| Supabase | Database, authentication, file storage and server functions, including PDF generation | European Union (Frankfurt, Germany) |
| Resend | Delivery of the emails the Customer sends from the Service | United States |
| Vercel | Hosting of the web application and share pages; cookieless performance analytics | United States |